vendor:
OP5 Monitor
by:
Peter Osterberg
7,5
CVSS
HIGH
Arbitrary root command execution
78
CWE
Product Name: OP5 Monitor
Affected Version From: 5.3.5
Affected Version To: 5.5.1
Patch Exists: YES
Related CWE: CVE-2012-0262, OSVDB-78065
CPE: a:op5:op5_monitor
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Linux, Unix
2012
OP5 welcome Remote Command Execution
This module exploits an arbitrary root command execution vulnerability in OP5 Monitor welcome. Ekelow AB has confirmed that OP5 Monitor versions 5.3.5, 5.4.0, 5.4.2, 5.5.0, 5.5.1 are vulnerable.
Mitigation:
Upgrade to the latest version of OP5 Monitor